Installing and Configuring System Center Configuration Manager (SCCM)


Getting Started with this Course

• 26min

System Center Configuration Manager - Features and Capibilities

• 31min

SCCM 1902 Lab Setup

• 50min

Installing SCCM 1902 Installation

• 1hr 17min

Configuration Manager Basics

• 1hr 53min

Updating SCCM

• 30min

SCCM Client Installation

• 46min

User and Device Collections

• 1hr 0min

Application Management

• 2hr 34min

Operating System Deployment

• 23min

Endpoint Protection

• 1hr 12min

• 37min

Problems and Solutions from the Message Board

• 14min

Creating and Managing Administrative Users

In this lecture you are going to learn how to create and manage your SCCM administrative users and groups.

In the SCCM console, navigate to Administration > Security > Administrative Users:

Inside the right pane you will see your administrative users and groups. Here you can right-click existing users to edit, refresh or remove them:

Right-click the default Administrator account and select Properties:

Here you will see three tabs; General, Security Roles and Security Scopes. General simply lists basic identifiable information about the user account. Security Roles allows you to define how much control you want the user or group to have. In this case, we can see that this user is a Full Administrator.

The Security Scopes tab allows you to define what objects the user will have “Full Administrator” permissions.

In small networks you would probably just go with the first option of All instances of the objects that are related to the assigned security roles. This associates the user with the All security scope as well as the All Systems and All Users and User Groups collections.

Selecting Only the instances of objects that are assigned to the specified security scopes and collections will associate the user with the Default security scope as well as the All Systems and All Users and User Groups collections. The main difference here is that this time the security scopes will be limited to that of the user account you used to create the account.

The Associate assigned security roles with specific security scopes and collections allows you to create specific associations between desired security roles and security scopes and collections.

Click Cancel and close the properties dialog. Now either select Add User or Group or right-click in the white pane below and select Add User or Group.

Now let’s define the following settings:

  • User or group name: SCCM Admins
  • Assigned security roles: Full Admin
  • Assigned security scopes and collections: All instances of the objects that are related to the assigned security roles

Now you will see the new AD group listed here with the “Full Administrator” security role:

Since we added an AD security group, this means any members of that group will now have Full Administrator permissions inside of SCCM.

